Scope
This policy covers all personal data we handle in the course of operating our business, including through our websites, our services, our products, our software, our platforms, our applications and our digital services. It is written to apply to offerings we introduce in future without amendment, so a new service is covered from the day it launches.
Where we operate a system on behalf of a client — for example, and without limitation, hosting or administering a platform that holds that client's own records — the client determines the purposes of that processing and we act on their instructions. In that arrangement the client is responsible for informing their own users, and this policy governs only our own handling of the data.
The data we handle
We collect only what a specific purpose requires. The categories below are illustrative of what we typically hold and are not an exhaustive list.
| Category | Typical contents | Where it usually comes from |
|---|---|---|
| Contact and business details | Name, business email address, telephone number, employer, role | Provided by you when you contact us or engage us |
| Engagement records | Correspondence, requirements, meeting notes, agreements, invoices | Generated in the course of working together |
| Technical and access records | Authentication events, administrative actions, system and security logs | Generated automatically by systems we operate or administer |
| Support records | Tickets, call records where telephony is in scope, and the content of support correspondence | Provided by you or generated when support is delivered |
| Recruitment data | Applications and supporting material, where you apply to work with us | Provided by you |
We do not seek special category data and ask that it is not sent to us unless a specific engagement genuinely requires it and an appropriate basis has been agreed in writing beforehand.
Why we handle it, and on what basis
| Purpose | Lawful basis where UK or EU law applies |
|---|---|
| Responding to enquiries and providing proposals | Steps taken at your request prior to entering a contract, or legitimate interests in responding to business enquiries |
| Delivering and supporting what we have been engaged to deliver | Performance of a contract, or legitimate interests where the contract is with your employer |
| Operating, securing and monitoring systems | Legitimate interests in keeping systems available, secure and auditable |
| Meeting accounting, tax and regulatory obligations | Compliance with a legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests, or compliance with a legal obligation |
Where we rely on legitimate interests we have considered whether those interests are overridden by your rights, and you may object as described under Your rights below. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal.
Who we share it with
We do not sell personal data, and we do not share it for advertising or profiling purposes. We share it only in the following circumstances.
- With service providers who process data on our instructions under a written agreement — for example, and without limitation, providers of hosting, communications, or business administration tooling.
- With a client, where the data was generated in the course of work carried out for that client.
- Where disclosure is required by law, by a court, or by a competent regulator.
- With professional advisers where necessary for advice, audit or the defence of legal claims.
- With a successor entity in connection with a reorganisation or transfer of the business, subject to this policy continuing to apply.
International transfers
We are established in the United States and deliver internationally, including to clients in the United States, Canada, the United Kingdom, the European Economic Area, the United Arab Emirates and the wider Middle East, Australia, and Pakistan. Personal data may therefore be transferred to, stored in, or accessed from countries other than the one you are in.
Where personal data protected by UK or EU law is transferred outside those jurisdictions, we rely on an appropriate transfer mechanism — an adequacy decision where one applies, or standard contractual clauses together with any supplementary measures the transfer requires. Where a specific engagement requires that data remain within a defined territory, that is agreed in the engagement documentation and implemented technically rather than promised generally.
How long we keep it
We keep personal data for as long as the purpose it was collected for requires, and then for any period a legal, tax, accounting or contractual obligation demands. Enquiry correspondence that does not lead to an engagement is kept only for as long as it is useful to the enquiry. Records relating to an engagement are generally kept for the duration of that engagement and for the limitation period applicable afterwards. Where we operate a system on a client's behalf, retention within that system is set by the client and configured accordingly.
Security
We apply access control on a least-privilege basis, use individual accounts rather than shared credentials for administrative access, protect data in transit using current transport encryption, restrict administrative interfaces to defined access paths, and log administrative activity. No system is immune from compromise, and any statement to the contrary should be treated with suspicion. Our practice is to reduce the likelihood of an incident and to limit what a single failure can reach.
If you believe you have found a security weakness in something we operate, please report it as described in our security policy rather than testing further.
Cookies and similar technologies
Our public website does not currently set cookies and does not run advertising, profiling or third-party analytics scripts. Where this changes, or where a platform we operate for you requires cookies to function, the position is described in our cookie policy.
Your rights
Depending on where you are and which law applies, you may have some or all of the following rights. We honour them where they apply and will tell you plainly if a specific right does not apply to your situation and why.
- Access — to be told whether we hold personal data about you and to receive a copy.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have data deleted where there is no continuing basis for keeping it.
- Restriction — to limit how we use data while an issue is resolved.
- Objection — to object to processing carried out on the basis of legitimate interests.
- Portability — to receive certain data in a structured, commonly used, machine-readable format.
- Withdrawal of consent — where processing is based on consent.
- Complaint — to raise the matter with the supervisory authority in your country.
Residents of certain jurisdictions have additional or differently framed rights, including the right not to be discriminated against for exercising them. Where we operate a system on behalf of a client and you are that client's customer or employee, please direct your request to that client in the first instance; we will assist them in responding.
To exercise a right, contact us using the details below. We may need to verify your identity before acting, and we will respond within the period the applicable law requires.
Children
Our services are provided to businesses and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We update this policy when our practices change or when a legal requirement changes. The effective date is shown at the top of this page. Where a change materially affects how we handle personal data, we will take reasonable steps to bring it to the attention of affected clients rather than relying on the updated page alone.
Contact
Questions about this document can be sent to info@kyconnects.com. We aim to respond to enquiries within 4–8 business hours.
Related documents
- Cookie Policy— what this website does and does not set
- Security Policy and Responsible Disclosure— how to report a vulnerability
- Terms & Conditions